Five days ago I went through the actual bills and precedents and concluded that the only lever Washington had on Kimi K3 was the window before its weights existed, and that the window would shut on release. Moonshot published on July 27, roughly 1.4TB across 96 shards, on the date it had promised at launch.
Nothing happened. No executive order. No Entity List designation. No sanctions. No procurement restriction. The threats were real and on the record, and the enforcement never arrived.
What Was Threatened
This was not vapour. On July 22, White House science and technology chief Michael Kratsios accused Moonshot of running “a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” Treasury Secretary Scott Bessent, the same day:
— Scott Bessent, US Treasury Secretary, July 22 2026Open source is not open season on American IP. When [Chinese] firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.
Axios reported the administration was weighing Commerce Entity List additions, an NSA advisory, and an executive order limiting US companies to hosting Chinese models only if they could guarantee security and accept liability for breaches. All three were revivals of proposals killed the previous year.
Five days later the file was on Hugging Face and mirrored globally. The lever had a shelf life and it expired.
The Question Everyone Was Arguing About Got Measured
The genuinely new thing this week was not political. On July 23, the UK AI Safety Institute and the US CAISI published a joint preliminary assessment of K3’s cyber capabilities. The numbers are worth sitting with:
- Exploit development: 0 of 41 samples achieved arbitrary code execution, against 20 of 41 for leading models.
- Cyber range progression: K3 averaged step 17 of 32. The most capable US models reached 28.5 of 32.
- Overall, K3 “performs significantly below the most recent frontier cyber-capable models.”
And, in the same report: K3’s “safeguards did not prevent it from attempting cyber exploit development or offensive cyber operations.”
So the open model tries and fails. The closed frontier models succeed and refuse. To measure the closed models at all, the institutes had to test them with system-level safeguards disabled.
That is the finding, stated plainly. The frontier offensive capability everyone worried about escaping into the open is not in the open model. It is in the ones behind APIs, held back by guardrails that a government evaluator can switch off and that a determined attacker has other ways around. The open weights are the less capable artifact by a wide margin.
Anthropic Answered, and Agrees More Than Expected
On July 27, Dario Amodei published Anthropic’s position. The headline is a flat denial: “Anthropic has never advocated for a ban on open-weights models,” prefaced with “let me state it clearly so that there is no doubt.”
I called that framing correctly four days earlier, when I wrote that “Dario wants to outlaw open source” was mostly his critics’ framing. But my own follow-up then treated the industry letter’s distillation paragraph as a rebuttal aimed at Anthropic, and that reading was too neat. Here is Amodei on the letter:
— Dario Amodei, Our position on open-weights models, July 27 2026I agree with much of it: open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control. Concerns about distillation should be addressed through targeted legal and commercial frameworks.
“Targeted legal and commercial frameworks” is the letter’s own phrase, from the paragraph I argued was aimed at him. He endorses it. Kratsios said the same thing on July 22, that “legitimate AI distillation… plays a vital role in this open innovation ecosystem.” Three parties who were reported as being at war agree on the remedy.
What Amodei actually disputes is one sentence wide, and it is the one that matters here:
— Dario Amodei, July 27 2026I don’t agree with the letter’s assertions that open-weights models necessarily make it easier to develop safeguards or that broad access to capabilities necessarily helps defenders more than attackers. It seems at least as likely to me that the opposite will be true.
That is the argument I have been making across four posts, named and rejected by the person who runs the company whose models I ship with daily. It deserves a straight answer rather than a victory lap, so: the AISI and CAISI numbers landed four days before he wrote that, and they cut against him on cyber specifically. The open model is measurably worse at offensive work. The capability gap runs the other way.
His stronger ground is biology, where he argues the attacker-defender asymmetry is real because “defense against these agents is a multi-year operational task in the best case.” I don’t have data to refute that and I’m not going to pretend the cyber result generalises to it. Different threat model, different clock speed, and the cyber evidence is one preliminary assessment of one model.
What “Open” Turned Out to Mean
The release itself deserves less reverence than either side gave it.
- The licence is not MIT. It is Modified MIT: a separate commercial agreement is required above $20M of Model-as-a-Service revenue over any 12 months, plus prominent “Kimi K3” branding above 100M monthly users. Real terms, not open source in the sense the word usually carries.
- Almost nobody can run it. 2.8T parameters, 104B active, roughly 1.4TB of weights. The r/LocalLLaMA release thread hit 2,339 upvotes and is mostly people working out that they can’t: “You need an 8-way B300 or MI350X or a Rubin NVL8 or a cluster thereof to actually run this.” Someone priced a rig at $550k.
- The distillation case is contested by the people who looked hardest. A MATS study using persona probing found that “Kimi, however, has no second character: prompting it as Claude does not change its style or behaviour,” where GLM-5.2 genuinely does have a selectable Claude persona. That pattern fits training-data contamination better than targeted distillation. Dean Ball, now at OpenAI and with no reason to be generous: “I don’t think its performance can be explained away by distillation or anything like that.”
Free to download, capped by licence, unrunnable without half a million dollars of silicon. “Open weights” describes the file, not the access.
What This Doesn’t Settle
- One assessment, one model, preliminary. The AISI result is a snapshot of K3 as it shipped, on cyber only. Fine-tunes remove guardrails, and the next release resets the measurement.
- The closed-model comparison was rigged toward capability. Testing frontier models with safeguards disabled measures what they can do, not what they will do for an ordinary user. That is the right way to measure danger and the wrong way to measure deployed behaviour.
- Nothing happening is not the same as nothing being possible. Procurement rules and government-use bans still work, still bind contractors, and would not have needed the pre-release window.
- Anthropic’s third ask survived unexamined. Mandatory pre-release safety testing for “all sufficiently capable models, open and closed” is the real proposal, and it is a gate. You cannot test-gate a file after publication, so for open weights the testing requirement is the restriction, whatever it is called. The commenters asking “what model doesn’t have dangerous capabilities?” are asking the right question about where that threshold sits.
The Takeaway
- The prediction held. The only enforceable lever expired on release, exactly on the timeline, and the administration did not pull it.
- The public fight was narrower than the coverage. Everyone agrees legitimate distillation is fine and nobody was advocating a category ban. That was a week of theatre over a phantom.
- The real disagreement is empirical, and it started getting answered. Whether open access helps defenders or attackers is testable. Two state institutes tested one slice of it and the open model came out weaker, not scarier.
- Discount the word “open.” A licence with a revenue cap and a 1.4TB payload is a different thing from what the debate implied on both sides.
The most-restricted artifact in this story turned out to be the one nobody was trying to restrict: a frontier closed model, tested with its safety systems switched off, producing working exploits twenty times out of forty-one.



